Skip to content
Review

Systematization of Knowledge: Platforms, Pedagogies, and Practices for Effective ICS/OT Security Training

· 0 citations · 5 references

TL;DR

The analysis of various sources reveals that accessible virtualization technologies, especially containerization, are highly effective, along with active learning methods that include constructionism and GBL for motivational and cognitive benefits, and scenario-based training should model complete incident procedures and IT/OT integration complexities.

View source

Similar papers

Review Open access Jul 2026

Evaluating Security Challenges in Digital Access Systems for Technology-Enabled Vocational Education: A Systematic Literature Review

The rapid expansion of technology-enabled vocational education has increased reliance on digital access systems that regulate entry to learning platforms, simulations, and assessment environments. This study examines how security challenges in these systems affect learning continuity in vocational education and identifies factors that intensify disruption risks. A systematic review of peer-reviewed studies published between 2020 and 2025 was conducted using five academic databases, applying predefined inclusion criteria and synthesizing findings through descriptive and thematic analysis. Results show that weaknesses in data confidentiality, integrity, and especially system availability frequently interrupt instructional activities, particularly practice-based learning dependent on digital laboratories and assessment tools. Disruptions are often amplified by misalignment between technical infrastructure, user practices, and institutional governance, with institutions lacking governance capacity and user training facing higher risks of learning interruption. Although technical and administrative mitigation strategies exist, they are often implemented without sufficient alignment to pedagogical needs. The study concludes that digital access security should be treated not merely as a technical concern but as a prerequisite for equitable and resilient vocational learning, calling for integrated socio-technical and pedagogically informed security strategies.

K. Agyeibi, Budi Mulyanti, Agus Setiawan et al. · 0 citations
Review Open access Aug 2026

DevSecOps for Secure Software Development: A Systematic Literature Review of Practices, Benefits, and Adoption Barriers

The implementation of DevSecOps has emerged as an essential strategy for incorporating security from the early stages of software development. Its adoption allows for reducing vulnerabilities, streamlining threat detection, and complying with security regulations. Using a Systematic Literature Review, the study retrieved thirty research articles that met the requirements for inclusion in the review. The objective is to provide an overview of the current state of existing empirical studies on DevSecOps practices, which can help define strengths and areas of opportunity, and allow for planning future studies. Finally, studies reveal several advantages to adopting the DevSecOps approach, such as creating more secure and resilient software, improving cybersecurity defenses, and fostering a safe and open culture through communication and collaboration among development teams. However, the literature highlighted specific challenges or barriers to adopting this approach, such as organizational resistance, cultural transformations, and the complexity of implementing new security tools and procedures.   Spanish-language metadata / Metadatos en españolTítulo en español: DevSecOps para el desarrollo seguro de software: una revisión sistemática de la literatura sobre prácticas, beneficios y barreras de adopciónResumen: La implementación de DevSecOps se ha consolidado como una estrategia esencial para incorporar la seguridad desde las primeras etapas del desarrollo de software. Su adopción permite reducir vulnerabilidades, agilizar la detección de amenazas y cumplir con las normativas de seguridad. Mediante una revisión sistemática de la literatura, el estudio recuperó treinta artículos de investigación que cumplieron los criterios de inclusión establecidos. El objetivo es ofrecer una visión general del estado actual de los estudios empíricos existentes sobre las prácticas de DevSecOps, con el fin de identificar sus fortalezas y áreas de oportunidad, así como facilitar la planificación de futuras investigaciones. Finalmente, los estudios revelan varias ventajas asociadas con la adopción del enfoque DevSecOps, entre ellas el desarrollo de software más seguro y resiliente, la mejora de las defensas de ciberseguridad y el fomento de una cultura segura y abierta mediante la comunicación y la colaboración entre los equipos de desarrollo. Sin embargo, la literatura también destaca desafíos o barreras específicas para la adopción de este enfoque, como la resistencia organizacional, las transformaciones culturales y la complejidad de implementar nuevas herramientas y procedimientos de seguridad. Palabras Claves: DevSecOps; desarrollo seguro de software; ciclo de vida del desarrollo de software; revisión sistemática de la literatura; seguridad por diseño; seguridad continua; prácticas de seguridad del software; resiliencia de ciberseguridad; detección de amenazas; barreras para la adopción de DevSecOps; cultura organizacional; automatización de la seguridad.   Smart citations: https://scite.ai/reports/10.61467/2007.1558.2026.v17i4.1299Dimensions.Open Alex.

Patricia Martínez-Moreno, J. A. Vergara-Camacho, Víctor Adrián Lueváno-Mondragon et al. · 0 citations
Review Open access Jul 2026

Cybersecurity and Digital Learning in Higher Education: Emerging Threats, Protective Technologies, and Future Directions

Higher education institutions occupy a uniquely exposed position in the global cybersecurity landscape. The convergence of large-scale digital transformation, open-access network philosophies, diverse user populations, and repositories of sensitive personal and research data has made universities consistently attractive targets for a wide spectrum of cyber threats. This critical review synthesises peer-reviewed literature and authoritative institutional evidence published between 2018 and March 2026, examining the evolving threat landscape confronting higher education institutions, with particular attention to ransomware, phishing, data breaches, insider threats, and the emerging risks associated with generative artificial intelligence. Protective technologies including zero-trust architectures, AI-driven intrusion detection, multi-factor authentication, and cloud security frameworks are critically assessed in relation to their applicability within academic environments. The human dimension of cybersecurity receives substantial attention, with cybersecurity awareness, training effectiveness, and behavioural factors examined across student and staff populations. Governance, policy, and regulatory considerations are discussed alongside the specific vulnerabilities of digital learning platforms and learning management systems. Findings indicate that whilst technological solutions are advancing, the most persistent vulnerabilities in higher education institutions remain structural and human, demanding integrated responses that combine robust technology governance with sustained cultural change. The review concludes by identifying key future directions, including quantum-resilient cryptography, federated security models, and sector-wide intelligence sharing.

A. Osijirin, Leonard C. Anigbo, Oliver Okechukwu et al. · 1 citation
Review Open access Aug 2026

Evolving Policies, Effectiveness, Tools and Factors of Cybersecurity Awareness in Schools in the Context of AI: A Systematic Review, 2015-2025

This study analyzes the critical success factors, tools, and effectiveness of Artificial Intelligence (AI) in cybersecurity awareness within educational institutions, covering the period 2015–2025. The research is based on a systematic review approach, collecting and evaluating empirical and theoretical studies published in international scientific databases. Findings reveal that the adoption of AI in awareness programs relies on technological infrastructure, teachers’ digital literacy, students’ acceptance, and institutional support. Regarding tools, the most prominent are chatbots, recommendation systems, immersive environments, and machine learning algorithms that enable personalized training. In terms of effectiveness, results indicate improvements in knowledge retention, changes in students’ digital habits, and an increased ability to detect threats such as phishing or malware. This article contributes to the literature by providing a synthesis of the advances and challenges in applying AI to educational cybersecurity, highlighting the importance of sustainable strategies that strengthen the digital security culture across schools and universities.

Brandon Morales-Fernández, Carlos Alberto, Chiri Huanca et al. · 0 citations
Review Open access Jul 2026

Strategies, Regulations and Mechanisms for Protecting Student Data in University Digital Repositories: A Systematic Review

The digitalization of educational services has increased the exposure of student information to security and privacy risks. This research addresses the need to understand the strategies, regulations, and technologies used to protect data in university digital repositories. A systematic literature review was conducted in recognized databases (WOS, Scopus, and ACM), from which 30 studies meeting the inclusion criteria were selected. The findings showed that higher education institutions face complex challenges in risk management, regulatory compliance (such as GDPR), and the adoption of international standards such as ISO/IEC 27001 and 27002. Additionally, emerging methods such as homomorphic encryption and secure multiparty computation were identified, as well as vulnerability analysis tools that improve system security. Digital curation, awareness programs, and backup policies were also highlighted as essential components. Overall, the results suggest that protecting student data requires a comprehensive approach that combines legal frameworks, technical capabilities, and organizational culture. This review provides a solid conceptual foundation for developing effective strategies for educational data governance and recommends future research in real-world implementation scenarios.

Marco Yamba-Yugsi, J. Ortega-Castro, Jorge Maldonado-Mahauad et al. · 0 citations
Open access Aug 2026

An Integrated University Digital Transformation Model Combining IT Governance, Interoperability, Cloud Security Assessment and Data Analytics: The UTMACH Case in Ecuador

The case indicates that university digital transformation is strengthened when technological implementation is integrated with formal governance, systematic assessment, evidence-based planning, and institutional accountability.

Jennifer Célleri-Pacheco, Fernanda Tusa Jumbo, Oswaldo Chuquirima Camacho et al. · 0 citations